Hwtacacs Authentication And Authorization Of Telnet Users - H3C S5600 Series Operation Manual

Hide thumbs Also See for H3C S5600 Series:
Table of Contents

Advertisement

Operation Manual – AAA
H3C S5600 Series Ethernet Switches
<Sysname> system-view
# Adopt AAA authentication for Telnet users.
[Sysname] user-interface vty 0 4
[Sysname-ui-vty0-4] authentication-mode scheme
[Sysname-ui-vty0-4] quit
# Create and configure a local user named telnet.
[Sysname] local-user telnet
[Sysname-luser-telnet] service-type telnet
[Sysname-luser-telnet] password simple aabbcc
[Sysname-luser-telnet] quit
# Configure an authentication scheme for the default "system" domain.
[Sysname] domain system
[Sysname-isp-system] scheme local
A Telnet user logging into the switch with the name telnet@system belongs to the
"system" domain and will be authenticated according to the configuration of the
"system" domain.
Method 2: using local RADIUS server
This method is similar to the remote authentication method described in
RADIUS Authentication of Telnet/SSH
Change the server IP address, and the UDP port number of the authentication
server to 127.0.0.1, and 1645 respectively in the configuration step "Configure a
RADIUS scheme" in
Enable the local RADIUS server function, set the IP address and shared key for
the network access server to 127.0.0.1 and aabbcc, respectively.
Configure local users.

2.5.3 HWTACACS Authentication and Authorization of Telnet Users

I. Network requirements
You are required to configure the switch so that the Telnet users logging into the switch
are authenticated and authorized by the TACACS server.
A TACACS server with IP address 10.110.91.164 is connected to the switch. This
server will be used as the authentication and authorization server. On the switch, set
both authentication and authorization shared keys that are used to exchange
messages with the TACACS server to aabbcc. Configure the switch to strip domain
names off usernames before sending usernames to the TACACS server.
Configure the shared key to aabbcc on the TACACS server for exchanging messages
with the switch.
Users. However, you need to:
Remote RADIUS Authentication of Telnet/SSH
2-36
Chapter 2 AAA Configuration
Remote
Users.

Advertisement

Table of Contents
loading

This manual is also suitable for:

S5600-26cS5600-26c-pwrS5600-26fS5600-50cS5600-50c-pwr

Table of Contents